首页 | 官方网站   微博 | 高级检索  
     

面向网络空间的访问控制模型
引用本文:李凤华,王彦超,殷丽华,谢绒娜,熊金波.面向网络空间的访问控制模型[J].通信学报,2016,37(5):9-20.
作者姓名:李凤华  王彦超  殷丽华  谢绒娜  熊金波
作者单位:1. 中国科学院信息工程研究所信息安全国家重点实验室,北京 100093;2. 北京电子科技学院信息安全系,北京 100070
基金项目:国家自然科学基金面上基金资助项目(No.61170251);国家高技术研究发展计划(“863”计划)基金资助项目(No.2015AA016007);国家自然科学基金-广东联合基金资助项目(No.U1401251);国家自然科学基金青年基金资助项目(No.61502489)
摘    要:提出一种面向网络空间的访问控制模型,记为CoAC。该模型涵盖了访问请求实体、广义时态、接入点、访问设备、网络、资源、网络交互图和资源传播链等要素,可有效防止由于数据所有权与管理权分离、信息二次/多次转发等带来的安全问题。通过对上述要素的适当调整可描述现有的经典访问控制模型,满足新的信息服务和传播模式的需求。给出了CoAC管理模型,使用Z-符号形式化地描述了管理模型中使用的管理函数和管理方法。该模型具有极大的弹性、灵活性和可扩展性,并可进一步扩充完善,以适应未来信息传播模式的新发展。

关 键 词:网络空间安全  访问控制  管理场景  信息服务模式  信息传播模式
收稿时间:4/1/2016 12:00:00 AM

Novel cyberspace-oriented access control model
Feng-hua LI,Yan-chao WANG,Li-hua YIN,Rong-na XIE,Jin-bo XIONG.Novel cyberspace-oriented access control model[J].Journal on Communications,2016,37(5):9-20.
Authors:Feng-hua LI  Yan-chao WANG  Li-hua YIN  Rong-na XIE  Jin-bo XIONG
Affiliation:1. The State Key Laboratory of Information Security,Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100093,China;2. Department of Information Security,Beijing Electronic Science and Technology Institute,Beijing 100070,China
Abstract:A novel cyberspace-oriented access control model was proposed, termed as CoAC, which avoided the threats by comprehensively considering vital factors, such as the access requesting entity, general tense, access point, device, networks, resource, internet-based interactive graph and chain of resource transmission. By appropriately adjusting these factors, CoAC emulated most of typical access control models and fulfilled the requirements of new information service patterns and dissemination modes. The administrative model of CoAC was also presented and the functions and methods for administrating CoAC were described by utilizing Z-notation. CoAC is flexible and scalable, it can be further refined and expanded to figure out new opportunities and challenges in the upcoming access control techniques.
Keywords:cyberspace security  access control  administrative scene  information service pattern  information dissemination mode
点击此处可从《通信学报》浏览原始摘要信息
点击此处可从《通信学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号